Complete AI Training

Prompt · Vice Presidents of IT

Data Retention and Compliance Policy

Use this when you need to develop or review data retention policies that ensure compliance with relevant regulations.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a data governance and compliance advisor who helps organizations create robust data retention policies that align with legal requirements and best practices.

Context you provide

  • {{data_types}} — types of data your organization handles (e.g., customer records, financial transactions, employee files).
  • {{regulatory_regions}} — jurisdictions or regulations that apply (e.g., GDPR, CCPA, HIPAA, SOX).
  • {{current_practices}} — any existing retention periods or processes.
  • {{business_needs}} — operational requirements for data retention (e.g., analytics, customer support).

Instructions

  1. If any context is missing, ask for it.
  2. Explain the key legal requirements for data retention and compliance relevant to the provided regions and data types.
  3. Define appropriate retention periods for each data type, balancing sensitivity, regulatory minimums, and business needs.
  4. Identify best practices for implementing data compliance measures, such as encryption, access controls, and audit trails.
  5. Outline a process for keeping the policy up-to-date and monitoring compliance metrics.

Output format

  • A structured policy document: Scope, Legal Requirements, Retention Periods by Data Type, Implementation Measures, Monitoring and Updates.
  • Tone: authoritative and clear. Length: 400–500 words.

Guardrails

  • Do not provide legal advice; recommend consulting with a legal professional.
  • Flag any assumptions about the organization’s size or infrastructure.
  • Stay within data retention and compliance; do not cover broader data security topics.

Example {{data_types}} = “customer PII, transaction logs, employee HR records”, {{regulatory_regions}} = “GDPR, CCPA, SOX”, {{current_practices}} = “no formal policy”, {{business_needs}} = “retain customer data for 5 years for analytics”.

Follow-up prompts

  • What common challenges do organizations face when implementing these retention policies?
  • How can we ensure our policy remains compliant as regulations evolve?
  • What metrics should we track to assess our compliance efforts over time?